Compliance 6 min read

How to Know If Your Company Handles CUI

Controlled Unclassified Information is often present in organizations that don't realize it. Here's how to identify it and understand what that means for your security obligations.

Controlled Unclassified Information (CUI) is a federal designation for information that requires safeguarding under law, regulation, or government-wide policy — but is not classified. The challenge for most companies is that CUI can enter an organization without anyone explicitly labeling it, and the security obligations that come with it apply regardless of whether you knew the data was CUI.

If your organization works with the federal government or its contractors, there is a reasonable chance you handle CUI. The consequences of not knowing — and not protecting it — include contract loss, False Claims Act liability, and disqualification from future DoD work.

Here is how to determine whether CUI applies to your organization — and what to do if it does.

What CUI Actually Is

CUI is defined by the National Archives and Records Administration (NARA) CUI Registry, which lists over 100 specific categories of information that qualify. The categories span defense, financial, legal, health, research, and critical infrastructure domains.

CUI is not the same as classified information. It does not require a security clearance to handle. But it does require specific safeguarding measures — and those measures are defined by NIST SP 800-171, which is the foundation of CMMC compliance.

Common CUI categories relevant to defense contractors and their supply chains include:

Defense and procurement

  • Technical data related to defense contracts (drawings, specifications, test results)
  • Export-controlled information (EAR, ITAR)
  • Controlled technical information (CTI) on DoD contracts
  • Acquisition-sensitive information

Financial and legal

  • Personally identifiable information (PII) subject to federal privacy requirements
  • Tax information and financial records under federal jurisdiction
  • Legal proceedings and law enforcement sensitive information

Health and safety

  • Health information subject to federal programs (not just HIPAA)
  • Safety act information
  • Critical infrastructure security information

Research and intellectual property

  • Federally funded research and development results
  • Patent applications before publication
  • Proprietary business information shared under federal contract

Signs Your Organization Likely Handles CUI

You do not need to see the letters "CUI" on a document to be handling it. If any of the following apply, your organization likely has CUI obligations:

  • You have a contract with a federal agency or a prime contractor on a federal program
  • Your contract includes DFARS clause 252.204-7012 (Safeguarding Covered Defense Information)
  • You receive technical drawings, specifications, or test data from a defense contractor
  • You provide cloud services, IT support, or managed services to a federal contractor
  • Your contract references NIST SP 800-171 compliance requirements
  • You handle data marked "For Official Use Only" (FOUO), "Sensitive But Unclassified" (SBU), or similar legacy markings
  • You store, process, or transmit data on behalf of a federal agency or prime contractor

What Is Not CUI

Not all sensitive information is CUI. The designation is specific to federal law, regulation, or government-wide policy. The following are generally not CUI:

  • Commercially available information with no federal nexus
  • Your own proprietary business information not shared under a federal contract
  • Information marked confidential under a commercial NDA only
  • Public information released by the government
  • Information from state or local government contracts (unless federal funding is involved)

If You Handle CUI: What to Do Next

01

Review your contracts

Look for DFARS clauses, references to NIST SP 800-171, or language about "covered defense information," "controlled technical information," or "controlled unclassified information." If you find them, CUI obligations apply.

02

Identify where the data flows

Map where CUI enters your organization, where it is stored, who accesses it, and how it leaves. This becomes your system boundary — the scope of your CMMC or NIST 800-171 assessment.

03

Assess your current controls

NIST SP 800-171 has 110 security requirements across 14 control families. A gap assessment against these requirements tells you where you stand and what you need to fix before a formal assessment.

04

Understand your CMMC level

If your contract involves CUI, you likely need CMMC Level 2 compliance — which requires a third-party assessment (C3PAO) for most contracts. Understanding your level determines your timeline and investment.

Download the CMMC & NIST 800-171 Readiness Checklist to assess where your organization stands against the 110 NIST 800-171 requirements.

The Cost of Not Knowing

CMMC enforcement is accelerating. DoD contracts now require contractors to self-attest or obtain third-party certification depending on the CUI sensitivity level. Organizations that discover they handle CUI after a contract award — or after an incident — face compressed timelines, potential contract loss, and in some cases False Claims Act liability for misrepresenting their compliance posture.

The first step is simply knowing. A contract review and a brief scoping conversation with a qualified advisor can answer the question definitively — and give you a clear picture of what NIST 800-171 compliance looks like for your organization.

Frequently asked questions

What is the difference between CUI and classified information?

Classified information requires a security clearance to access and is marked with classification levels (Confidential, Secret, Top Secret). CUI does not require a clearance but does require specific safeguarding measures under federal law or regulation. Many defense contractors handle CUI without ever handling classified information.

Does CUI have to be labeled to be CUI?

No. CUI obligations apply based on the nature of the information, not whether it has been labeled. If your organization receives technical drawings, specifications, or other data from a defense contractor under a federal contract, that data may be CUI regardless of whether it is marked as such.

What security requirements apply to organizations that handle CUI?

Organizations that handle CUI under DoD contracts are required to implement the 110 security requirements in NIST SP 800-171. CMMC Level 2 formalizes these requirements and adds third-party assessment obligations for most contracts involving CUI.

What happens if my organization handles CUI but is not compliant?

Non-compliance with CUI safeguarding requirements can result in contract termination, disqualification from future DoD work, and in cases where compliance was misrepresented, False Claims Act liability. The risk increases as CMMC enforcement accelerates.

How do I find out if my contracts require CMMC?

Review your contracts and subcontracts for DFARS clause 252.204-7012 (Safeguarding Covered Defense Information), references to NIST SP 800-171, or language about CUI or controlled technical information. If you are a subcontractor, ask your prime contractor directly.